ralebit[.]com
فحص التصيد والأمان للنطاق ralebit.com
“raleBIT: The Easiest Way to Buy Crypto with Confidence”
ralebit.com — المحتوى غير متوفر (HTTP 502). انتحال العلامة التجارية: Aave; نوع الاحتيال: Brand Impersonation. ملخص الأدلة: VT 6/93 (alphaMountain.ai, Certego, Fortinet, Gridinsoft, SOCRadar); URLQuery 1 alert; URLScan no malicious verdict; GSB no flag; Spamhaus DBL_PHISH; BL 0; PD 73/100. مسجّل النطاق: NiceNIC.
يبقى تحليل PhishDestroy AI المفصل أدناه باللغة الإنجليزية للحفاظ على السجل الجنائي الرقمي الأصلي.
PhishDestroy first observed ralebit.com on Jan 30, 2026. Positive findings were recorded by VirusTotal, Spamhaus DBL, and URLQuery. Evidence score: 73/100.
VirusTotal recorded 6 detections among 93 engines: alphaMountain.ai, Certego, Fortinet, Gridinsoft, SOCRadar, URLQuery on Feb 25, 2026 at 01:15 UTC. Spamhaus DBL: DBL_PHISH on Jul 14, 2026 at 10:36 UTC. URLQuery recorded 1 threat-system alert on Jan 30, 2026 at 16:31 UTC. AlienVault OTX listed 1 community pulse reference (not vendor detections) on Mar 1, 2026 at 10:41 UTC. The external blocklist snapshot contained no matches on Aug 7, 2026 at 10:20 UTC. Google Safe Browsing returned no flag on Mar 3, 2026 at 04:14 UTC. URLScan completed without a malicious verdict (score 0) on Mar 26, 2026 at 12:15 UTC.
HTTP 502 was recorded on Aug 7, 2026 at 01:36 UTC; content was unavailable. Latest classified outcome: registration hold observed; cause registrar client hold; mechanism client hold; observed actor NICENIC INTERNATIONAL GROUP CO., LIMITED on Aug 7, 2026 at 02:13 UTC. Registration records list NiceNIC International Group Co., Limited as the registrar. At collection time, the domain resolved to 104.21.44.117. Collected metadata identifies Aave as the apparent target. Captured page title: “raleBIT: The Easiest Way to Buy Crypto with Confidence”. PhishDestroy classified the observed content as Brand Impersonation. DOM analysis completed on Apr 23, 2026 at 03:22 UTC; stored DOM score 10/100. IoC extraction completed on Aug 2, 2026 at 04:14 UTC; stored 0 format-validated wallet addresses and 0 Telegram indicators.
Stored full analysis24/07/2026
Analysis of ralebit.com, observed on July 24 2026, indicates a brand impersonation operation targeting Aave. The domain was registered through NiceNIC International Group Co., Limited on February 21 2026. Infrastructure shows the domain resolves to 104.21.44.117, an address owned by Cloudflare, Inc. (AS13335) located in the United States. Nameservers are nick.ns.cloudflare.com and nucum.ns.cloudflare.com, confirming Cloudflare hosting. No SSL certificate was observed, and the site is currently taken offline. The page title retrieved before takedown reads "raleBIT: The Easiest Way to Buy Crypto with Confidence", aligning with the declared target brand Aave.
Threat intelligence: The domain appears on three security blocklists and has been blocked by PhishDestroy, MetaMask, and SEAL. AlienVault OTX includes the domain in one pulse. VirusTotal scans show six of ninety‑three security vendors flagged the domain, indicating partial detection. Gridinsoft assigns a trust score of 1 out of 100, reflecting extreme suspicion. The low trust score and blocklist presence corroborate the malicious classification.
Uncertainties remain regarding the specific phishing kit or content served, as no SSL certificate or detailed page capture is available. The offline status prevents real‑time verification of payloads or credential‑harvesting forms. Nevertheless, the combination of brand‑targeted page title, registrar data, Cloudflare IP, blocklist entries, and vendor detections provides sufficient evidence to label the site as a confirmed brand impersonation scam. Defenders should add ralebit.com to internal block and deny lists, monitor DNS queries for the resolved IP and associated Cloudflare nameservers, and propagate the detection to upstream security services. Continuous observation of any re‑registration attempts or similar domain patterns is recommended, given the recent creation date and low trust score.
مؤشرات الأمان
استخبارات أمن الشبكات Registrar Integrity Alert
| Detection System | Indicator | Verdict | Alert |
|---|---|---|---|
| Nextron YARA rules | ralebit.com/app-resources-d5/main.f04664c1385e68c1186a.v2.js |
malware | Unique code from Jetriz, Swid & Jeniva of the Tetris framework |
مسار الاستجابة للتهديدات Pipeline
حالة قوائم الحظر العامة
لقطة محفوظة
معلومات النطاق
التفاصيل الفنيةDNS، أسماء المجال البديلة (SAN) في بروتوكول SSL، الطوابع الزمنية
ICANN OVERSIGHT
الاعتماد وسياق RAA
الاعتماد وسياق RAA
حصلت ICANN على أموالها. أما المساءلة فلم تصل.
بالنسبة إلى نطاق gTLD هذا، يعمل المسجّل المذكور أعلاه بموجب عقد مع ICANN. وتحصّل ICANN رسوماً سنوية ومتغيرة ورسومًا قائمة على المعاملات مرتبطة بعمليات التسجيل والتجديد والنقل.
الاعتماد: جرت الاستفادة منه مالياً. المساءلة: يُرجى التحقق مرة أخرى لاحقاً.
ثم يبدأ السحر: تكتب ICANN البند RAA §3.18، ويتولى المسجّل التحقيق في إساءة الاستخدام داخل قاعدة عملائه، ويقدّم الضحايا الأدلة مجاناً، بينما تنتظر كل طبقة أن يتحرك طرف آخر. إذا كان ذلك يجعل الضحايا يشعرون بمزيد من الأمان، فممتاز—لقد أدّت الفاتورة مهمتها.
Latest Classified Outcome 2026-08-07 04:13:16 UTC
تحليل VirusTotal
الأدلة المؤرشفة
الأدلة والتقارير الخارجية
هل تأثرت بهذا الموقع؟
إذا أدخلت بيانات اعتماد الحساب أو المعلومات الشخصية أو معلومات الدفع أو قمت بتنزيل ملف من هذا النطاق، فاتخذ إجراءً فوريًا. فيما يلي موارد لمساعدتك في الإبلاغ عن الحادث وحماية نفسك.
أبلغ السلطات المحلية
حدد بلدك للحصول على الاتصالات الرسمية المتعلقة بالجرائم الإلكترونية أو إنشاء مسودة شكوى →.
حول هذا التقرير: ralebit.com
يقدم هذا التقرير أحدث الأدلة المخزنة المتاحة لـ PhishDestroy. يتم عرض الطوابع الزمنية للمصدر حيثما كان ذلك متاحًا؛ يمكن أن تتغير أحكام التوفر والبائعين بعد التجميع.
عرض الموقع الذي تم التقاطه عنوان الصفحة “raleBIT: The Easiest Way to Buy Crypto with Confidence” وربما ينتحل شخصية Aave.
اعتبارًا من 07/08/2026، كان لدى ralebit.com اكتشافات من محركات الأمان 6.
إذا كنت تعتقد أن هذه القائمة غير دقيقة، تقديم استئناف. للتعرف على منهجيتنا، قم بزيارة صفحة الأسئلة الشائعة.
تحقق من أي نطاق
تحليل التهديدات باستخدام قائمة الحظر المخزنة، وWHOIS، وDNS، وأدلة الفحص العامة
امسح الآنالإبلاغ عن محاولة تصيد احتيالي
أرسل النطاقات المشبوهة إلى قاعدة بيانات التهديدات الخاصة بنا — ساهم في حماية المجتمع
إبلاغتحديثات فورية حول التهديدات
تقارير التصيد الاحتيالي الأخيرة وتغييرات التوفر الملحوظة
مراقبةابقَ على اطلاع، وابقَ آمنًا
راقب التهديدات في الوقت الفعلي أو اعترض على هذا الإدراج إذا كنت تعتقد أنه إنذار كاذب